Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.18% | — | Microworld Technologies Escan AntivirusAI | 3/5/2024 | 17/6/2026 | A kernel handle leak issue in ProcObsrvesx.sys 4.0.0.49 in MicroWorld Technologies Inc eScan Antivirus could allow privilege escalation for low-privileged users. | |
| Analizada | Alta (7.2) | 1.9% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway DbasSectorFileToExecuteOnReset Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is required to exploit this… | |
| Analizada | Media (5.3) | 0.58% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (5.3) | 1.0% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.… | |
| Analizada | Alta (7.5) | 0.76% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Cryptograhic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.… | |
| Analizada | Alta (7.2) | 2.0% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the… | |
| Analizada | Alta (7.2) | 1.2% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this… | |
| Analizada | Media (6.5) | 1.5% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication… | |
| Analizada | Media (4.4) | 1.3% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to write arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this… | |
| Analizada | Alta (7.2) | 3.4% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Event Log Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the… | |
| Analizada | Alta (7.8) | 0.96% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Media (5.3) | 0.24% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The… | |
| Analizada | Crítica (9.8) | 2.0% | — | Trianglemicroworks Scada Data Gateway | 3/5/2024 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists due to the lack of… | |
| Aplazada | Media (6.5) | 0.28% | — | Pdfcrowd Save AS PDFAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 3.2.0. | |
| Aplazada | Media (5.9) | 0.32% | — | Pdfcrowd Save AS ImageAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Save as Image plugin by Pdfcrowd allows Stored XSS.This issue affects Save as Image plugin by Pdfcrowd: from n/a through 3.2.1 . | |
| Aplazada | Media (5.9) | 0.32% | — | Pdfcrowd Save AS PDFAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 3.2.1 . | |
| Aplazada | Media (6.5) | 0.50% | — | Pdfcrowd Word Replacer PROAI | 20/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Save as PDF plugin by Pdfcrowd Word Replacer Pro.This issue affects Word Replacer Pro: from n/a through 1.0. | |
| Modificada | Alta (8.8) | 0.22% | — | Automattic Crowdsignal Dashboard | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11. | |
| Modificada | Media (6.1) | 0.35% | — | Automattic Crowdsignal Dashboard | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11. | |
| Modificada | Media (4.8) | 0.40% | — | Themeum WP Crowdfunding | 15/1/2024 | 17/6/2026 | The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.42% | — | Themeum WP Crowdfunding | 8/1/2024 | 17/6/2026 | The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.28% | — | Themeum WP Crowdfunding | 28/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through 2.1.6. | |
| Modificada | Media (4.3) | 0.51% | — | Microweber | 15/12/2023 | 17/6/2026 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Media (4.8) | 0.45% | — | Themeum WP Crowdfunding | 11/12/2023 | 17/6/2026 | The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.5) | 0.85% | — | Microweber | 8/12/2023 | 17/6/2026 | An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method. |